Hi @socuser , This grouping works as expected as each incident has 1000
alerts. rsa.respond.alertrule.batch-size=1000 value decides how many
alerts are part of each incident.
Hi @socuser , You will have to stop aggregation during this data
transfer to the new NAS. make sure all packetdb,metadb,sessiondb, index
contents are copied over to the new NAS. Then update the configuration
of Archiver with new NAS directories for m...